Bug ID 1165422
Summary VUL-1: CVE-2020-9548: jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.2
Hardware Other
URL https://smash.suse.de/issue/254023/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter wolfgang.frisch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-9548

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction
between serialization gadgets and typing, related to
br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9548
https://github.com/FasterXML/jackson-databind/issues/2634
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548
https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062


You are receiving this mail because: